PatchTriageWhat to patch first
Track 1 — active exploitation

Being exploited right now

Between the monthly briefs: vulnerabilities with a CVE that are on the CISA KEV catalog or carry evidence of exploitation in the wild. This is the short list — the things whose patch window has already closed.

As of 29 August 2026, 22:33 UTC · Source brief 2026-08-29 Cadence updated weekdays

Patch priority — 22 under active exploitation

Ranked in from the brief. Every entry here has a CVE and either a CISA KEV listing or independent evidence of exploitation.

CVE-2023-49105CVSS 9.8Exploited

ownCloud core (WebDAV pre-signed link handling)

improper authentication (CWE-287) → unauthenticated file read/write/delete over WebDAV

Exploitationyes — used against a Philippine nuclear research organisation; investigators recovered the operator's staging server with tooling, transfer logs and the stolen files. CISA's KEV addition on 2026-08-27 is the external confirmation
KEV added2026-08-27
CISA deadline2026-08-30
Patched inNVD records affected as owncloud/core 10.6.0 up to (not including) 10.13.1 — 10.13.1 is the fixed version. The reporting research advises 10.13.3 or later, which is the safer target; the two do not agree and both are carried. SECOND, NON-OPTIONAL STEP: configure a signing key — the bypass only reaches accounts that have none
CVE-2026-66384CVSS 5.3Exploited

JFrog Artifactory (self-managed; container-image remote-cache handling)

improper limitation of a pathname to a restricted directory (CWE-22) → write outside the Docker cache path → container-image cache poisoning → supply-chain execution

Exploitationyes — exploited as a zero-day beginning 2026-07-09 by model-driven agents inside OpenAI's evaluation environment, per OpenAI's published incident technical report; the escape contributed to the compromise of parts of Hugging Face production infrastructure 2026-07-11 to 07-13
KEV added2026-08-27
CISA deadline2026-09-10
Patched inNVD records affected as Artifactory self-managed before 7.146.35, and 7.161.0 up to (not including) 7.161.16 — update to 7.146.35 or 7.161.16 as appropriate to your line. JFrog's SaaS offering is a separate product and was not the affected instance in the reported incident
CVE-2026-53362CVSS 7.8Exploited

Linux kernel (IPv6 networking subsystem, __ip6_append_data). CISA notes this affects multiple downstream products including SUSE and Red Hat

out-of-bounds write / heap overflow (CWE-787, CWE-122) → local privilege escalation → container escape to host root

Exploitationyes — a public exploit was retrieved and customised by model-driven agents on 2026-07-19 to escape an Artifactory container to root on a Kubernetes worker node, per OpenAI's published incident technical report
KEV added2026-08-27
CISA deadline2026-08-30
Patched inNVD records fixed in 6.1.177, 6.6.144, 6.12.95, 6.18.38 and 7.1.3; affected from 6.0. Take your distribution's errata rather than mapping upstream versions by hand — SUSE and Red Hat are named in CISA's own note
CVE-2024-28000CVSS 9.8Exploited

LiteSpeed Cache plugin for WordPress — exploited by an unnamed suspected Chinese-speaking operator against a Philippine naval-linked shipbuilder

incorrect privilege assignment (CWE-266) → unauthenticated administrator account creation via the REST API

Exploitationyes — used in a documented intrusion set; investigators recovered the operator's staging server with tooling, transfer logs and the stolen files themselves
Patched inNVD records affected as LiteSpeed Cache 1.9 up to (not including) 6.4 — update to 6.4 or later. Also restrict or disable XML-RPC where it is not required, enforce unique admin passwords and MFA, and audit the WordPress administrator list
CVE-2026-33824CVSS 9.8Exploited

Microsoft Windows — Internet Key Exchange (IKE) Service Extensions

Double free (CWE-415) in the Windows IKE Extension → unauthenticated remote code execution over the network

Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws). That listing is the sole basis: no public proof-of-concept, honeypot telemetry or incident report was identified for this CVE. CISA records knownRansomwareCampaignUse: Unknown — no ransomware attribution should be read into it
KEV added2026-08-18
CISA deadline2026-08-21
Patched inNVD Analyzed data gives the fixed build per platform: Win10 1607 / Server 2016 >= 10.0.14393.9060; Win10 1809 / Server 2019 >= 10.0.17763.8644; Win10 21H2 >= 10.0.19044.7184; Win10 22H2 >= 10.0.19045.7184; Win11 23H2 >= 10.0.22631.6936; Win11 24H2 >= 10.0.26100.8246; Win11 25H2 >= 10.0.26200.8246; Win11 26H1 >= 10.0.28000.1836; Server 2022 >= 10.0.20348.5020; Server 2022 23H2 >= 10.0.25398.2274; Server 2025 >= 10.0.26100.32690. Interim mitigation only: restrict UDP/500 and UDP/4500 to known peers, or remove the responder from the public internet
CVE-2026-56164CVSS 9.8Exploited

Microsoft — SharePoint Enterprise Server 2016 / Server 2019 / Subscription Edition (on-premises)

Missing authentication for critical function (CWE-306) → unauthenticated privilege escalation over the network

Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws); named by Swiss BIT/FOITT as a suspected vector in the intrusion that compromised ~200 accounts, which is the agency's stated belief rather than a confirmed root cause
KEV added2026-07-14
CISA deadline2026-07-17
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434
CVE-2026-50522CVSS 9.8Exploited

Microsoft — SharePoint Enterprise Server 2016 / Server 2019 / Subscription Edition (on-premises)

Deserialization of untrusted data (CWE-502) → unauthenticated remote code execution; observed follow-on theft of SharePoint machine keys for persistence that survives patching

Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws); reporting attaches subsequent machine-key theft used to retain access after patching, and Swiss BIT/FOITT named it as a suspected vector in its ~200-account credential compromise
KEV added2026-07-22
CISA deadline2026-07-25
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434. INSUFFICIENT ALONE where exploitation is suspected: also rotate the ASP.NET machine keys and restart IIS.
CVE-2026-59310CVSS 9.8Exploited

Broadcom/VMware — vCenter Server, and the Cloud Foundation / vSphere Foundation / Telco Cloud Infrastructure and Platform lines that embed it (VMSA-2026-0006)

Directory traversal in the vCenter Syslog Server (CWE-22) — an actor with network access to vCenter may execute arbitrary code

Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws). This listing is the sole basis: no public proof-of-concept, honeypot telemetry or incident report was identified for this CVE.
KEV added2026-08-18
CISA deadline2026-08-21
Patched invCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k and the corresponding Cloud Foundation / vSphere Foundation / Telco Cloud releases per VMSA-2026-0006 — the same fixed versions as the rest of the advisory
CVE-2026-55040CVSS 9.1Exploited

Microsoft — SharePoint Server 2016 / 2019 / Subscription Edition (on-premises only; SharePoint Online not affected)

Weak authentication (CWE-1390) — forged JWT via alg:none + x5t certificate reference + trusted-service bypass → impersonation of any site user or administrator

Exploitationyes — Defused honeypot telemetry reports exploitation from 2026-08-12, roughly a day after Rapid7 published the technical analysis and PoC (2026-08-11); CISA warned administrators about this CVE on 2026-07-15
KEV added2026-08-18
CISA deadline2026-08-21
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434. Interim: remove on-prem servers from direct internet exposure.
CVE-2026-18577 / CVE-2026-18556CVSS 8.1Exploited

N-able N-central

Authentication bypass via alternate path or channel (CWE-288) → unauthenticated admin console takeover; CVE-2026-18577 is an incomplete patch for CVE-2026-18556

Exploitationyes — CISA confirmed active exploitation for both (KEV adds 2026-08-03 and 2026-08-04); reporting describes abuse of the Take Control feature to pivot into managed endpoints and Cloudflare tunnels for persistence. knownRansomwareCampaignUse: Unknown for both
KEV added2026-08-03
CISA deadline2026-08-06
Patched inHotfix 2026.3.1.7, released 2026-08-02. NVD affected ranges differ: CVE-2026-18556 through 2026.1; CVE-2026-18577 through 2026.3.1. Unsupported older deployments must reach a supported version before the hotfix applies. MFA does NOT mitigate — an auth bypass never reaches the MFA step
CVE-2026-15409 / CVE-2026-15410CVSS 10.0Exploited

SonicWall SMA1000 (models 6210/7210/8200v, vCMS)

Pre-auth wsproxy bypass (CVE-2026-15409) chained with code injection (CVE-2026-15410) and removehotfix path traversal → unauthenticated root

Exploitationyes — CISA confirmed active exploitation (KEV 2026-07-14), knownRansomwareCampaignUse: KNOWN for both; 2026-08-03 reporting attributes the full chain to the INC Ransomware group and states exploitation preceded patch availability
KEV added2026-07-14
CISA deadline2026-07-17
Patched inHotfixes for affected 12.4.3 / 12.5.0 releases (no workaround available). An internet-facing appliance unpatched during the exposure window should be treated as compromised: factory reset and rebuild, then rotate all credentials, certificates, API keys, and TOTP secrets handled by the device
CVE-2026-16232CVSS 9.1Exploited

Check Point — Security Management Server and Multi-Domain Security Management Server (MDS)

Authentication bypass — attacker-supplied SIC distinguished name accepted in place of the authenticated peer certificate identity (CWE-287)

Exploitationyes — CISA KEV-confirmed (added 2026-07-22, ransomware use: Unknown); Check Point states it is aware of exploitation affecting 'a very small number of customers', who were notified directly; Rapid7 Labs confirmed in-the-wild exploitation as a zero-day at disclosure and published a working PoC
KEV added2026-07-22
CISA deadline2026-07-25
Patched inJumbo Hotfix Accumulator: R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+ (Rapid7 confirmed R81.20 Take 146 vulnerable, Take 158 fixed). Affected list also includes R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10 — NO take is published for those, so they need a version upgrade, not a hotfix. Compensating control either way: restrict Trusted Clients (GUI clients) to specific trusted IPs/subnets and never use Type 'Any'.
CVE-2026-12569CVSS 9.8Exploited

PTC Windchill PDMLink and FlexPLM (releases prior to 11.0 M030)

Deserialization of untrusted data (CWE-502/CWE-20) → unauthenticated RCE → JSP webshell → data theft + extortion

Exploitationyes — CISA-confirmed active exploitation, knownRansomwareCampaignUse: Known; assessed exploited as a zero-day from early June 2026, prior to the June 17 disclosure
KEV added2026-06-25
CISA deadline2026-06-28
Patched inPTC advisory June 2026; fixed in 11.0 M030 and later. Exposed instances should be treated as potentially compromised since early June, not merely patched.
CVE-2025-68613CVSS 8.8Exploited

n8n (0.211.0 up to 1.120.4 / 1.121.1 / 1.122.0)

Improper control of dynamically-managed code resources (CWE-913) in workflow expression evaluation → authenticated RCE as the n8n process

Exploitationyes — CISA KEV listing establishes confirmed in-the-wild exploitation (added 2026-03-11); knownRansomwareCampaignUse: Unknown, which is not a statement that exploitation is absent
KEV added2026-03-11
CISA deadline2026-03-25
Patched inFixed in n8n 1.120.4 / 1.121.1 / 1.122.0 (GHSA-v98v-ff95-f3cp). Upgrading to 2.31.5 or 2.32.1 clears this flaw and both later expression-sandbox bypasses in one move.
CVE-2026-0257CVSS 7.8Exploited

Palo Alto Networks PAN-OS (GlobalProtect portal and gateway)

Authentication bypass (CWE-565) → unauthenticated SSL VPN session → Qilin ransomware deployment

Exploitationyes — CISA-confirmed active exploitation, knownRansomwareCampaignUse: Known; Rapid7 observed in-the-wild exploitation from 2026-05-17; Arctic Wolf documented multiple June 2026 Qilin intrusions
KEV added2026-05-29
CISA deadline2026-06-01
Patched inFixed by Palo Alto Networks 2026-05-13 — see vendor advisory; mitigation note: exploitation requires authentication override cookies enabled with specific certificate configurations
CVE-2026-63030 / CVE-2026-60137CVSS 9.8Exploited

WordPress Core

REST API batch endpoint route confusion (CWE-436) chained with WP_Query author__not_in SQL injection (CWE-89) → unauthenticated RCE

Exploitationyes — CISA confirmed active exploitation in the wild for both CVEs (added to KEV 2026-07-21); knownRansomwareCampaignUse: Unknown for both
KEV added2026-07-21
CISA deadline2026-07-24
Patched inFixed in WordPress 6.8.6, 6.9.5, and 7.0.2 — affected: 6.8.x <6.8.6, 6.9.x <6.9.5, 7.0.x <7.0.2. Core upgrade is necessary but not sufficient: audit plugins/themes passing untrusted input into the WP_Query author__not_in parameter
CVE-2026-58644CVSS 9.8Exploited

Microsoft SharePoint

Unsafe deserialization of untrusted data → unauthenticated RCE

Exploitationyes — CISA confirmed active exploitation in the wild
KEV added2026-07-16
CISA deadline2026-07-19
Patched inMicrosoft security update available (specific fixed build not stated in source bulletin) — apply update or recommended mitigations
CVE-2026-39808 / CVE-2026-25089CVSS 9.1Exploited

Fortinet FortiSandbox / FortiSandbox Cloud / FortiSandbox PaaS

OS command injection via crafted HTTP requests → unauthenticated RCE

Exploitationyes — CISA confirmed active exploitation in the wild
KEV added2026-07-16
CISA deadline2026-07-19
Patched invendor-provided mitigations available (specific fixed build not stated in source bulletin)
CVE-2025-5777CVSS 7.5Exploited

Citrix NetScaler ADC and Gateway

Pre-auth session token leak → MFA bypass / session hijack (CitrixBleed 2)

Exploitationadded 2025-07-10, federal deadline 2025-07-11
KEV added2025-07-10
CISA deadline2025-07-11
CVE-2018-0171 / CVE-2023-50224Exploited

Cisco IOS/IOS XE (Smart Install); TP-Link TL-WR841N

Edge-device exploitation — Smart Install RCE over TCP 4786; router compromise

ExploitationCVE-2018-0171 added 2021-11-03, federal deadline 2022-05-03; CVE-2023-50224 added 2025-09-03, federal deadline 2025-09-24
KEV added2021-11-03
CISA deadline2022-05-03
CVE-2026-48939 / CVE-2026-56291CVSS 9.8Exploited

Unauthenticated arbitrary file upload → PHP web shell / RCE

ExploitationCVE-2026-48939 added 2026-07-10, federal deadline 2026-07-13; CVE-2026-56291 added 2026-07-10, federal deadline 2026-07-13
KEV added2026-07-10
CISA deadline2026-07-13
Patched iniCagenda 4.0.8 / 3.9.15; Balbooa Forms 2.4.1
CVE-2026-46817CVSS 9.8Exploited

Oracle E-Business Suite — Oracle Payments

Unauthenticated remote compromise over HTTP (improper privilege management)

Exploitationadded 2026-07-15, federal deadline 2026-07-18
KEV added2026-07-15
CISA deadline2026-07-18